Clickjacking Vulnerability in sifchain.finance
S
Sifchain
Submitted None
Actions:
Reported by
lemon_in-the_spoon
Vulnerability Details
Technical details and impact analysis
Hello team - Greetings!
Hope you are fine. sifchain.finance website is vulnerable to Clickjacking. NOT ONLY THE HOME PAGE IS VULNERABLE, ALL THE PAGES IN THE WEBSITE IS VULNERABLE TO CLICKJACKING. And it has to be fixed because, Clickjacking is an attack that tricks the user to click a webpage element which is invisible or disguised as another element.
PROOF OF CONCEPT:
I have shared the screenshot and also shared the HTML file so that it will be easier for you to validate.
Have a nice day! Looking forward for your positive response.
Much Regards,
Suraj SK
## Impact
It is dangerous because with good combination of stylesheets, iframes, and text boxes, user can be led to believe they are typing in the password to their email or bank account, but are instead typing into an invisible frame controlled by the attacker. So it has to be fixed
Report Details
Additional information and metadata
State
Closed
Substate
Duplicate
Submitted
Weakness
UI Redressing (Clickjacking)